Fedora/RHEL ã§å°å
¥ããã¦ãã crypto-policies
ã cygwin ã«ãããããã«è¦ãããã©ãããããããã¯ä½ï¼ã¨æã£ãã®ã§èª¿ã¹ãã
crypto-policies
ã«ã¤ãã¦ç¥ãããå ´åã¯ä»¥ä¸ã®è¨äºãèªãã°ãããã
æ°ã«ãªã£ãã®ã¯ã©ããã¦ããã cygwin ã«ãå°å ¥ããã¦ããã®ãï¼ã¨ããç¹ã
æåã«ããã«æ°ã¥ããã®ã¯ ruby-puma ã®ããã±ã¼ã¸åã®æã§ãfedora ã® patch ã«ã©ããããã®ãããã®ããªãã¸ããªãè¦ãããrubygem-puma-3.6.0-fedora-crypto-policy-cipher-list.patch ã¨ãã patch file ããã£ã¦ããã®ä¸èº«ãã²ã£ããã£ãããã
diff --git a/ext/puma_http11/mini_ssl.c b/ext/puma_http11/mini_ssl.c index 7e0fd5e..88c4652 100644 --- a/ext/puma_http11/mini_ssl.c +++ b/ext/puma_http11/mini_ssl.c @@ -336,7 +336,7 @@ sslctx_initialize(VALUE self, VALUE mini_ssl_ctx) { SSL_CTX_set_cipher_list(ctx, RSTRING_PTR(ssl_cipher_filter)); } else { - SSL_CTX_set_cipher_list(ctx, "HIGH:!aNULL@STRENGTH"); + SSL_CTX_set_cipher_list(ctx, "PROFILE=SYSTEM"); } #if OPENSSL_VERSION_NUMBER < 0x10002000L
SSL_CTX_set_cipher_list
㯠OpenSSL ã®é¢æ°ã§ããã«ããããããããã® patch ãé©ç¨ããã "PROFILE=SYSTEM"
ã¨ãã Fedora/RHEL å®ç¾©ã®æååããã¼ãã³ã¼ãããã¦ãã¾ãããOpenSSL å´ãç¥ããªãæååã渡ãã¦ããå®è¡æã¨ã©ã¼ã«ãªããªãã®ãï¼
ã¨ãããã㧠OpenSSL å´ã®ãªãã¸ããªãè¦ããã対å¿ãã patch ãé©ç¨ãã¦ãã
ã¨ãªãã¨ãcygwin ã® OpenSSL ã«ããã® patch ãé©ç¨ããã¦ããã°ãruby-puma ã«ã rubygem-puma-3.6.0-fedora-crypto-policy-cipher-list.patch ãé©ç¨ããæ¹ãæã¾ããã¨ãããã¨ã«ãªãã
ã¨ããããã§ç¢ºèªããããcygwin å´ã§ãé©ç¨ãã¦ãã
commit log ãé¡ãã¨ãfedora patches ãåãè¾¼ã¿ã ããã¿ã¤ãã³ã° (1.1 ç³»ã«ç§»è¡) ã§å ¥ã£ã模æ§ã
ãã®ãã¨ã« "PROFILE=SYSTEM"
ã®ã»ãã«ã©ããããã®ãããã®ãï¼ãªã©ã調ã¹ã¦ãããæçµçã« crypto-policies
ã«ãã©ãçããã¨ããããã
ã¡ãªã¿ã«å ¬å¼ã«ãããã¸ãã®è©±ãæ¸ãã¦ãããã¥ã¡ã³ãã¯ãªããããä»åº¦ cygwin-app ML ã§ã§ãè¨ãã¦ã¿ããã